提出新型正交层与渐进损失,显著提升神经网络的认证鲁棒性。
Enhancing Certified Robustness via Block Reflector Orthogonal Layers and Logit Annealing Loss
- 设计块反射正交层,增强正交结构表达能力。
- 引入对数渐进损失,提升多数样本的分类间隔。
- 在多个数据集上实现当前最优认证鲁棒性,适合安全敏感场景。
Lipschitz神经网络因其可提供认证鲁棒性而广受关注。本文提出一种新颖高效的块反射正交(BRO)层,提升了正交层在构建更具表现力的Lipschitz神经网络架构方面的能力。同时,通过理论分析Lipschitz神经网络的本质,设计了一种采用渐进机制的新损失函数,使模型对多数数据点的分类边界更加清晰。该方法使所提出的BRONet——一个简洁而有效的Lipschitz神经网络——在CIFAR-10/100、Tiny-ImageNet和ImageNet上均达到当前最优的认证鲁棒性水平。大量实验与实证分析验证了其优越性。代码已开源:https://github.com/ntuaislab/BRONet。
原文摘要 · Abstract (English)
Lipschitz neural networks are well-known for providing certified robustness in deep learning. In this paper, we present a novel, efficient Block Reflector Orthogonal (BRO) layer that enhances the capability of orthogonal layers on constructing more expressive Lipschitz neural architectures. In addition, by theoretically analyzing the nature of Lipschitz neural networks, we introduce a new loss function that employs an annealing mechanism to increase margin for most data points. This enables Lipschitz models to provide better certified robustness. By employing our BRO layer and loss function, we design BRONet - a simple yet effective Lipschitz neural network that achieves state-of-the-art certified robustness. Extensive experiments and empirical analysis on CIFAR-10/100, Tiny-ImageNet, and ImageNet validate that our method outperforms existing baselines. The implementation is available at https://github.com/ntuaislab/BRONet.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。